Q: You run a shell script as the ENTRYPOINT that spawns multiple background worker processes. When you `docker stop` the container, it always takes exactly 10 seconds (the timeout) before stopping, and the workers don't clean up properly. What is the root cause?
When Docker sends SIGTERM via docker stop, it delivers the signal to PID 1 inside the container. If PID 1 is a shell script (/bin/sh or /...
#Docker #Must enable BuildKit #L2 #Containers #Linux
🎙️ Candidate Opening & Architectural Context
""In an interview, I explain how we diagnosed container runtime failures without guessing. The interviewer is testing: Signal handling, PID 1 behavior, `exec` in entrypoint scripts.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
When Docker sends SIGTERM via docker stop, it delivers the signal to PID 1 inside the container. If PID 1 is a shell script (/bin/sh or /bin/bash), the shell does NOT forward signals to its child processes by default. The shell itself ignores SIGTERM, so nothing happens for 10 seconds until Docker sends SIGKILL.
- Use
execto replace the shell with the main process: the last line of your entrypoint script should beexec ./my-workerinstead of./my-worker. This makes the worker PID 1 and it receivesSIGTERMdirectly. - Trap signals in the shell script if you must manage multiple processes:
- Use
--initflag (docker run --init) to injecttinias PID 1, which properly forwards signals and reaps zombie processes.
2️⃣
Remediation & Permanent Safeguards
*Fixes:*
#!/bin/bash
trap 'kill $(jobs -p); wait' SIGTERM SIGINT
./worker1 &
./worker2 &
wait
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Use exec to replace the shell with the main process: the last line of your entrypoint script should be exec ./my-worker instead of."
⚡ 60-Second Elevator Pitch Talking Points
- Use exec to replace the shell with the main process: the last line of your entrypoint script shou...
- Trap signals in the shell script if you must manage multiple processes:
- Use --init flag (docker run --init) to inject tini as PID 1, which properly forwards signals and ...
Advertisement